com-meta-web[.]framer[.]website
“Login | MetaMask | crypto*”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
The domain com-meta-web.framer.website was observed delivering a brand‑impersonation campaign targeting MetaMask. The site presented the page title “Login | MetaMask | crypto*” and was classified as a crypto scam. Registration data show the domain was created on 19 Nov 2021 through CSC Corporate Domains, Inc., and it resolves to the IPv4 address 52.223.52.2, an Amazon.com, Inc. (AS16509) host located in the United States. DNS resolution uses four Amazon Route 53 name servers: ns‑1243.awsdns‑27.org, ns‑1818.awsdns‑35.co.uk, ns‑336.awsdns‑42.com, and ns‑792.awsdns. The server presents a Let’s Encrypt certificate (issuer “E7”) and supports HSTS and HTTP/3.
Technology fingerprints indicate the use of Framer Sites, React, and modern HTTP features. Threat intelligence lists the domain on a single security blocklist and records a block by PhishDestroy. VirusTotal analysis shows seven of ninety‑five scanners flag the domain, confirming malicious intent. The HTTP response returned a 404 status, and the current operational status is offline. Analysis indicates that the infrastructure is typical of a copy‑cat phishing kit hosted on cloud services, leveraging legitimate TLS to increase credibility.
The limited blocklist presence suggests the domain may have been short‑lived or recently taken down. Uncertainty remains regarding the exact payload delivered, as the page content has not been captured beyond the title. Defenders should continue to block the domain at network perimeter, monitor for any resurgence of the same host or similar sub‑domains, and add the observed IP address 52.223.52.2 to reputation feeds. Organizations that use MetaMask should educate users about the official login URL and encourage verification of TLS certificates. Ongoing surveillance of the registrar CSC Corporate Domains, Inc. and the associated AWS name servers is advised to detect future impersonation attempts.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin